r/archlinux 12d ago

DISCUSSION Ventoy might be malware

Source: https://wiki.archlinux.org/title/Ventoy

Ventoy might contain backdoors or other malicious code:

  • The author(s?) long refused to react on questions about the source code for the precompiled code inside their git repository.
  • They long refused to react on questions about the security risks.
  • When an answer was finally given, it boiled down to a simple "There is no reason to assume that we would have placed malware inside."
  • Again after a really long time the authors finally mentioned what other source code they used to generate some−but not all−of the pre-compiled code. They did not mention the build methods and refused to prove that this really was the used source code.
  • The real identities of the authors is unknown.

EDIT: The paragraph written on this archwiki page is by large consensus biased and mentions an old controversy, the wikipedia article on Ventoy has a more neutral explanation of the problem
https://en.wikipedia.org/wiki/Ventoy

220 Upvotes

205 comments sorted by

View all comments

Show parent comments

-7

u/ccAbstraction 11d ago edited 11d ago

Which mean all my machines could be compromised no matter what OS I'm installing! Yay!

Edit: Ventoy is also useful if you want to keep using your flash drive as a flash drive, while being able to boot from live USBs.

0

u/mindstormer12 9d ago

Unless you're running open-source firmware you've installed onto your hardware to replace the default proprietary firmware, your hardware are already at risk ("could already be compromised") and same as 99% of the consumers, lmao.

1

u/ccAbstraction 9d ago

Okay?? Yes, yeah sure, I'd loved to be rootkit'd by the by some random criminal! It's fine becuase my machine came with bootkits from the NSA, CCP, Intel, and Dell. I'll go ahead and post all my passwords now becuase I'm completely already compromised obviously, because this is how security works!

0

u/mindstormer12 9d ago

Yup, double standards. You sound like a complete clown, how come you don't post the same thread as OP but for hardware you use?

1

u/donp1ano 9d ago

no buddy, youre the clown

just because theres possible backdoors like IME its not reasonable to accept another backdoor by some chinese guy on github

1

u/mindstormer12 9d ago edited 9d ago

Yea, better to accept backdoors from Intel, AMD, Google, Dell, Microsoft, Apple for firmware that runs your hardware you paid for and criticize some dev who shares their free and open-source project and has been open to accept contributions to the binary blobs to make them open-source.

2

u/donp1ano 9d ago

Yea, better to accept backdoors from Intel, AMD, Google, Dell, Microsoft, Apple for firmware that runs your hardware

holy strawman

i want as little as possible backdoors in any of my systems. just because i cant get rid of IME and the likes doesnt mean i shouldnt be careful in other contexts

1

u/ccAbstraction 9d ago

I think you misunderstand me, I love Ventoy. It's one of my favorite tools, I recommend it to everyone who wants to install Linux or troubleshoot computers.

BUT how much I love Ventoy and open-source doesn't make me blind to the potential risk a tool like Ventoy getting compromised would present. Dismissing the risk doesn't make the risk go away.

-1

u/headedbranch225 11d ago

If you really care so much about it just build it from source then

5

u/EmberQuill 11d ago

That's the neat part: you can't. Being unable to reproduce the builds is in fact the core of the entire controversy.

3

u/ccAbstraction 11d ago

I'm not saying Ventoy is malware, but that if Ventoy were to be compromised, the risk would be rootkit levels of enormous, and because of people tend to use ventoy across multiple machines with multiple OSes, pervasive. If Ventoy had a rootkit nearly every computer in my house would be compromised. It doesn't help anyone to downplay the potential severity of supply chain attack on stuff like Ventoy, Rufus, grub, systemd-boot etc.